Executive brief
Commvault CommServe, a central management and backup component used in enterprise data protection systems, contains a path traversal vulnerability that allows attackers to access and disclose sensitive information. An attacker exploiting this flaw could read confidential files from the server, potentially exposing backup metadata, credentials, or other business-critical data without requiring authentication.
Technical details
The vulnerability is a path traversal issue in CommServe that enables information disclosure through improper input validation or file access controls. The flaw allows an attacker to manipulate file paths to access files outside intended directories. This is a network-accessible vulnerability affecting CommServe installations on Linux and Windows platforms across multiple versions. Affected versions include 11.46.0–11.46.19, 11.44.0–11.44.19, 11.40.0–11.40.71, and 11.36.0–11.36.122. Commvault has released patches: 11.46.20, 11.44.20, 11.40.72, and 11.36.123 and higher resolve the issue.
Affected products
- Commvault CommServe 11.36.0–11.36.122, 11.40.0–11.40.71, 11.44.0–11.44.19, 11.46.0–11.46.19
Timeline
- 2026-09-08: disclosed: Vulnerability disclosed and advisory published